Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.64966
Category:Fedora Local Security Checks
Title:Fedora Core 10 FEDORA-2009-9386 (proftpd)
Summary:The remote host is missing an update to proftpd;announced via advisory FEDORA-2009-9386.;Note: This VT has been deprecated and is therefore no longer functional.
Description:Summary:
The remote host is missing an update to proftpd
announced via advisory FEDORA-2009-9386.
Note: This VT has been deprecated and is therefore no longer functional.

Vulnerability Insight:
Update Information:

This update has a large number of changes from previous Fedora packages. The
highlights are as follows:

- Update to upstream release 1.3.2a

- Fix SQL injection vulnerability at login (#485125, CVE-2009-0542)

- Fix SELinux compatibility (#498375)

- Fix audit logging (#506735)

- Fix default configuration (#509251)

- Many new loadable modules including mod_ctrls_admin and mod_wrap2

- National Language Support (RFC 2640)

- Enable/disable common features in /etc/sysconfig/proftpd

ChangeLog:

* Mon Sep 7 2009 Paul Howarth 1.3.2a-5

- Add upstream patch for MLSD with dirnames containing glob chars (#521634)

* Wed Sep 2 2009 Paul Howarth 1.3.2a-4

- New DSO module: mod_exec (#520214)

Solution:
Apply the appropriate updates.

This update can be installed with the yum update program. Use
su -c 'yum update proftpd' at the command line.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2009-0542
Bugtraq: 20090210 Another SQL injection in ProFTPd with mod_mysql (probably postgres as well) (Google Search)
http://www.securityfocus.com/archive/1/500823/100/0/threaded
Bugtraq: 20090210 ProFTPd with mod_mysql Authentication Bypass Exploit (Google Search)
http://www.securityfocus.com/archive/1/500851/100/0/threaded
Bugtraq: 20090210 Re: Another SQL injection in ProFTPd with mod_mysql (probably postgres as well) (Google Search)
http://www.securityfocus.com/archive/1/500833/100/0/threaded
Bugtraq: 20090211 Re: Re: Another SQL injection in ProFTPd with mod_mysql (probably postgres as well) (Google Search)
http://www.securityfocus.com/archive/1/500852/100/0/threaded
Debian Security Information: DSA-1730 (Google Search)
http://www.debian.org/security/2009/dsa-1730
https://www.exploit-db.com/exploits/8037
http://security.gentoo.org/glsa/glsa-200903-27.xml
http://www.mandriva.com/security/advisories?name=MDVSA-2009:061
http://www.openwall.com/lists/oss-security/2009/02/11/1
http://www.openwall.com/lists/oss-security/2009/02/11/3
http://www.openwall.com/lists/oss-security/2009/02/11/5
http://secunia.com/advisories/34268
CopyrightCopyright (C) 2009 E-Soft Inc.

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.